Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-125930

Backport support for loading multiple sets of x509 certificates for PQC hybrid mode

Linking RHIVOS CVEs to...Migration: Automation ...RHELPRIO AssignedTeam ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • qemu-kvm / General
    • None
    • rhel-virt-core
    • None
    • False
    • Hide

      None

      Show
      None
    • None

      To support hybrid mode for PQC, the TLS library (GNUTLS for QEMU) must be provided multiple distinct sets of certificates. One set using classic DSA algorithm, and one set using ML-DSA algorithm.

      This requires calling gnutls_certificate_set_x509_key() with different pem files loaded, which is not something QEMU is currently able to do.

      This task tracks the downstream backport

              rhn-engineering-berrange Daniel Berrangé
              rhn-engineering-berrange Daniel Berrangé
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: